# Sixteen queries against four setups on a real PostgreSQL 16

query                                        neither  guard only   role only  both
DELETE FROM order_items                      HARM     guard        db         guard
second statement drops a table               HARM     guard        db         guard
table the assistant must not see             HARM     guard        db         guard
email column of an allowed table             HARM     HARM         db         db
system catalog: list database roles          HARM     guard        HARM       guard
pg_sleep(3)                                  HARM     guard        db         guard
read a server file                           HARM     guard        db         guard
data-modifying CTE                           HARM     guard        db         guard
row locks on every order                     HARM     guard        db         guard
SELECT INTO makes a table                    HARM     guard        db         guard
2 billion generated rows                     HARM     guard        db         guard
turn read-only off for the session           HARM     guard        HARM       guard
cartesian product, allowed names only        HARM     HARM         db         db
(legit) join and group                       ok       ok           ok         ok
(legit) harmless comment                     ok       ok           ok         ok
(legit) date_part, not on the list           ok       guard        ok         guard

harmful outcomes out of 13 harmful queries: neither 13, guard only 2, role only 2, both 0

what the database said to the read-only role:
  DELETE FROM order_items                      ERROR: cannot execute DELETE in a read-only transaction
  second statement drops a table               ERROR: cannot execute DROP TABLE in a read-only transaction
  table the assistant must not see             ERROR: permission denied for table api_keys
  email column of an allowed table             ERROR: permission denied for table customers
  pg_sleep(3)                                  ERROR: canceling statement due to statement timeout
  read a server file                           ERROR: permission denied for function pg_read_file
  data-modifying CTE                           ERROR: cannot execute SELECT in a read-only transaction
  row locks on every order                     ERROR: cannot execute SELECT FOR UPDATE in a read-only transaction
  SELECT INTO makes a table                    ERROR: cannot execute SELECT INTO in a read-only transaction
  2 billion generated rows                     ERROR: canceling statement due to statement timeout
  cartesian product, allowed names only        ERROR: canceling statement due to statement timeout
